WIMM

Legal

Privacy Policy

Last updated 17 September 2026

We collect

Your email and phone number, and whatever you type into the app.

We do not collect

No analytics, no ad IDs, no location, no trackers of any kind.

Who else sees it

Cloudflare hosts it. Resend emails your code. Nobody else.

Deleting it

Settings → Delete account. Immediate, total, and not undoable.

WIMM records what you spend and what you owe. That is personal, so this page says plainly what the app collects, where it is kept, who else can see it, and how to delete it. If something here does not match what the app does, treat that as a bug and tell us.

What we collect

To sign you in. Your email address and your phone number. The code that signs you in is emailed; your phone number is recorded against the account but is not messaged, and is never used for marketing.

What you put in the app.

  • Expenses — the amount, the note you write, the date, and whether you marked it essential.
  • People you split with — the name you give them, and a UPI ID if you add one. These are typed by you. WIMM does not read your contacts.
  • Trips and groups, who is on them, and how each bill was divided.
  • Settlements — what has been paid off and what is still open.

What we do not collect. No analytics, no advertising identifiers, no location, no device fingerprinting, no crash-reporting SDK, no third-party trackers of any kind. The app contains no advertising or analytics code. We do not build a profile of you and we do not track you across other apps or websites.

Where it is kept

On your phone. Your ledger is stored on the device so the app works offline. Your sign-in token is held in the iOS Keychain. A small amount of non-sensitive bookkeeping — which account is signed in and how far the last sync got — is kept in the app's own preferences.

On our server. So the same ledger appears on any phone you sign into, a copy is kept in a database run on Cloudflare's infrastructure. It is reachable only with your sign-in token. Sign-in tokens are stored as hashes, not as the tokens themselves, so a copy of the database is not a set of working keys.

Who else sees it

Nobody, other than the two services that make the app work:

  • Cloudflare — hosts the server and the database.
  • Resend — delivers your sign-in code. It receives your email address and the code, and nothing else. It never receives your ledger.

We do not sell your data, we do not share it for advertising, and we do not hand it to anyone else except where the law requires it.

The people you split with do not need the app and do not have accounts. Their names live in your ledger. When you share a trip as a PDF or a spreadsheet, you are the one sending it, and where it goes after that is up to you.

Deleting your account

Open Settings in the app and tap Delete account. That erases the account and everything attached to it — expenses, people, trips, shares, settlements, and your email and phone number — from the server, and clears the ledger from the phone you are holding. Every other phone signed into that account is signed out.

It is immediate and it cannot be undone. There is no grace period and no copy kept for you to change your mind with. Export anything you want to keep first, from a trip's export menu.

Backups taken before the deletion may hold your data for a short period before they age out.

How long it is kept

Until you delete it. WIMM does not expire your ledger. Unused sign-in codes expire within minutes, and a sign-in token that goes unused for 90 days stops working and you are asked to sign in again.

Your rights

You can see everything the app holds about you, in the app itself — that is what the app is. You can export a trip as a PDF or a spreadsheet, edit or delete any expense, and delete the whole account. If you want a copy of what is held server-side, or you want something corrected and cannot do it in the app, write to us.

Depending on where you live, you may have further rights under laws such as India's Digital Personal Data Protection Act, the GDPR, or the CCPA. Use the contact below and we will act on those requests.

Children

WIMM is not directed at children under 13, and we do not knowingly collect their information.

Changes

If this policy changes in a way that matters, the date at the top changes and the app will say so before the change takes effect.

Contact

Before publishing

Set a real contact address. App Review checks that it works. Replace the address below, and the same one in support.html.

Questions, requests, or anything on this page that looks wrong: privacy@example.com.